Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
253 rules
Malicious Sparkling Pisces Backdoor C2 URI Pattern (via proxy)
This rule detects web requests to the fixed command-and-control URIs used by the Sparkling Pisces KLogEXE keylogger and FPSpy backdoor, which encode operator index parameters in PHP endpoints. These structured request patterns are specific to the toolset and indicate an infected host communicating with its controller.
HuntRule TeamWebproxyHigh153Premium2026-07-16Malicious GachiLoader C2 Beacon via X-Secret gachifamily Header
This rule detects HTTP traffic carrying the custom header value gachifamily or the GachiLoader C2 URI patterns /log and /richfamily, structural markers of the malware's command-and-control channel. These fixed protocol artifacts identify GachiLoader beaconing and tasking regardless of the C2 host in use.
HuntRule TeamWebproxyHigh2610Premium2026-07-16Malicious Katz Stealer Command-and-Control via katz-ontop User-Agent (via proxy)
This rule detects outbound HTTP requests carrying the distinctive katz-ontop token appended to the User-Agent string by the Katz Stealer implant during command-and-control communication. Adversaries leverage this hardcoded agent identifier to beacon to their infrastructure, making detection valuable for exposing active stealer command-and-control on the network.
HuntRule TeamWebproxyHigh102Premium2026-07-15Suspicious Command and Control via Discord or Telegram Bot API
This rule detects processes connecting to Discord webhook or Telegram bot API endpoints, a command and control and exfiltration channel used by the Tomiris APT. The actors tunneled tasking and stolen data through Discord webhooks and Telegram bot APIs to hide inside allowed messaging traffic. Non-browser processes contacting these bot endpoints strongly suggest abuse of trusted web services for C2.
HuntRule TeamWebproxyMedium123Premium2026-07-14Possible FortiWeb Authentication Bypass via Path Traversal to fwbcgi (via webserver)
This rule detects in the wild exploitation of Fortinet FortiWeb CVE-2025-64446 where a request to the cmdb API traverses the path to the internal fwbcgi handler to bypass authentication and create administrative users. The combination of the cgi-bin fwbcgi target and directory traversal is a reliable exploitation marker.
HuntRule TeamWebwebserverHigh101Premium2026-07-13SharePoint ToolShell Exploitation via ToolPane.aspx DisplayMode Edit (via webserver)
This rule detects requests to the SharePoint ToolPane.aspx endpoint with the DisplayMode Edit parameter, the exploitation vector for the ToolShell chain CVE-2025-53770 and CVE-2025-53771 that abuses Referer header handling to reach authenticated functionality without authentication. Adversaries use this request to deploy a webshell and steal ASP.NET machine keys.
HuntRule TeamWebwebserverHigh176Premium2026-07-12Possible Hive0051 GammaLoad C2 Beacon via Crafted User-Agent (via proxy)
This rule detects the distinctive User-Agent string used by Hive0051 GammaLoad implants for victim profiling during command-and-control. The agent appends a host token followed by an eight-character uppercase hex identifier and a keyword delimited by repeated semicolons and slash-dot sequences. This structure does not occur in standard browser traffic.
HuntRule TeamWebproxyMedium398Premium2026-07-12Possible ERMAC or Hook Android Malware C2 via PHP Endpoint URI Pattern
This rule detects HTTP requests to the distinctive /php/<token>.php/ URI structure used by the ERMAC and Hook Android banking malware families for encrypted command-and-control. The trailing-slash PHP endpoint carrying an AES and Base64 encoded body is a reliable network fingerprint of these C2 channels.
HuntRule TeamWebproxyMedium81Premium2026-07-12Possible GCleaner Loader C2 Check-in via cpa ping php Endpoint via proxy
This rule detects GCleaner loader command and control check-ins that request the /cpa/ping.php endpoint carrying a substr parameter. GCleaner is a pay per install loader that pulls follow on payloads after beaconing to its panel. The distinctive URI and query structure identifies the loader control channel independent of the rotating C2 IP addresses.
HuntRule TeamWebproxyHigh366Premium2026-07-11Possible SonicWall Credential Testing via userLogin Endpoint
This rule detects HTTP POST requests to the SonicWall /cgi-bin/userLogin endpoint, the interface used by NetExtender and web login for credential submission. In the observed campaign this endpoint is hit through commercial proxy infrastructure to test credentials against internet-facing SonicWall firewalls. A high rate of such POST requests indicates brute-force or credential-stuffing activity against the SSL-VPN login surface.
HuntRule TeamWebwebserverMedium286Premium2026-07-09Suspicious CurKeep Backdoor C2 API Endpoints (via proxy)
This rule detects web requests to the shell and file API endpoints used by the CurKeep backdoor for command-and-control in the Stayin Alive campaign. The fixed api shell and api file URI paths reflect the backdoor tasking channel and help surface implant traffic in proxy logs.
HuntRule TeamWebproxyLow152Premium2026-07-09Suspicious UPDTAE Backdoor Reverse Shell HTTP Beacon via Quad7 Operators
This rule detects HTTP requests carrying the hardcoded User-Agent value IOT together with POST requests to the /iot/post URI, the reverse shell beaconing pattern of the UPDTAE backdoor deployed by the Quad7 operators. The implant polls its C2 roughly every thirty seconds using this fixed header and path. The unusual static User-Agent and endpoint make this a reliable network indicator.
HuntRule TeamWebproxyHigh216Premium2026-07-07Malicious wp2shell User Agent in Web Requests (via webserver)
This rule detects inbound web requests carrying the wp2shell or rezwp2shell user-agent strings used by the exploitation tooling for CVE-2026-63030 and CVE-2026-60137. These agent values identify automated scanning and exploitation attempts against WordPress. The strings are tool-specific and rarely seen in benign traffic.
HuntRule TeamWebwebserverHigh232Premium2026-07-07Malicious SharePoint ToolShell Exploitation Request to ToolPane (via webserver)
This rule detects the exploitation request pattern for the SharePoint ToolShell vulnerabilities, a POST to the ToolPane endpoint in edit display mode with a spoofed SignOut referer used to bypass authentication. This request pattern corresponds to CVE-2025-49706 and CVE-2025-49704 exploitation rather than legitimate access.
HuntRule TeamWebwebserverHigh234Premium2026-07-05Possible Check Point SmartConsole Token Redemption Endpoint Access (via proxy)
This rule detects HTTP requests to the SmartConsole /cpmws/LoginSvcRemote token redemption endpoint. Rapid7 documented abuse of this SOAP endpoint to redeem forged SSO tokens as part of the CVE-2026-16232 authentication bypass against Check Point management servers. Legitimate SmartConsole clients also reach this endpoint so alerts should be correlated with unexpected source hosts or forged application token audit events.
HuntRule TeamWebproxyLow123Premium2026-07-03